update sshd configuration
This commit is contained in:
+19
-16
@@ -1,3 +1,22 @@
|
||||
* root
|
||||
* authorized_keys = heath
|
||||
* hpf-ans
|
||||
* system user
|
||||
* /usr/bin/bash
|
||||
* member of hpf-sudo-ntp
|
||||
* authorized_keys = hpf-ans
|
||||
* first
|
||||
* normal user
|
||||
* /usr/bin/bash
|
||||
* member of hpf-sudo
|
||||
* authorized_keys = heath, first
|
||||
* heath
|
||||
* normal user
|
||||
* /usr/bin/bash
|
||||
* member of hpf-sudo
|
||||
* authorized_keys = heath
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -61,21 +80,6 @@
|
||||
# use: systemd
|
||||
|
||||
|
||||
- name: Copy a new sudoers file into place, after passing validation with visudo
|
||||
ansible.builtin.template:
|
||||
src: /mine/sudoers
|
||||
dest: /etc/sudoers
|
||||
validate: /usr/sbin/visudo -cf %s
|
||||
|
||||
- name: Update sshd configuration safely, avoid locking yourself out
|
||||
ansible.builtin.template:
|
||||
src: etc/ssh/sshd_config.j2
|
||||
dest: /etc/ssh/sshd_config
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
validate: /usr/sbin/sshd -t -f %s
|
||||
backup: yes
|
||||
|
||||
|
||||
proxmox-clients
|
||||
@@ -85,7 +89,6 @@ hw:
|
||||
pve-kvm:
|
||||
|
||||
|
||||
users: first, heath, hpf-ans
|
||||
|
||||
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
||||
~heath/.ssh/authorized_keys
|
||||
|
||||
Reference in New Issue
Block a user